# Claude Code Plugin marketplaces and distribution

> Claude Code: Official, community, and internal marketplaces, version constraints, recommendations, security plugins, governance, and caching.

URL: https://docs.passion8.cc/en/docs/claude-code/plugin-marketplaces
Language: en
Publisher: Passion8

Plugins package skills, agents, hooks, MCP, LSP, and executables for reuse. A marketplace handles discovery, installation, versioning, and governance. For package structure, see [Plugins and skills](https://docs.passion8.cc/en/docs/claude-code/plugins).

## Marketplace model

| Concept | Meaning |
| --- | --- |
| Marketplace | Catalog of plugins |
| Plugin | Installed extension package |
| Source | Local path, repository, or relative catalog path |
| Scope | User/project/local installation |
| Reload | Apply changes with /reload-plugins |

First add a marketplace, then install selected plugins. Adding the catalog does not install everything.

## Official, community, and internal catalogs

| Catalog | Character | Recommendation |
| --- | --- | --- |
| claude-plugins-official | Official curated catalog, usually available | Still inspect plugin contents |
| claude-community | Community catalog with automated validation/screening | Review before enterprise approval |
| Demo catalog | Examples | Learn from it rather than depending blindly in production |
| Internal catalog | Company-maintained | Standard team workflows |

Install an official plugin:

```text
/plugin install github@claude-plugins-official
```

Update the catalog:

```text
/plugin marketplace update claude-plugins-official
```

Add the community catalog:

```text
/plugin marketplace add anthropics/claude-plugins-community
```

## Plugin categories

| Category | Examples | Value |
| --- | --- | --- |
| Code intelligence | TypeScript/Python/Go/Rust LSP | Diagnostics, definitions, references |
| Integrations | GitHub/GitLab/Sentry/Slack/Linear/Figma | Packaged connections |
| Security | security-guidance | Edit/turn/commit checks |
| Workflows | Commit, PR review, SDK/plugin development | Repeatable procedures |
| Output styles | Explanatory/Learning | Presentation and teaching |

LSP plugins commonly need a local language-server binary. If the Errors tab reports executable not found, install that binary.

## Create an internal catalog

```text
company-marketplace/
├── .claude-plugin/
│   └── marketplace.json
└── plugins/
    └── quality-review-plugin/
        ├── .claude-plugin/
        │   └── plugin.json
        └── skills/
            └── quality-review/
                └── SKILL.md
```

Marketplace manifest:

```json
{
  "name": "company-tools",
  "owner": {
    "name": "DevTools Team",
    "email": "devtools@example.com"
  },
  "plugins": [
    {
      "name": "quality-review-plugin",
      "source": "./plugins/quality-review-plugin",
      "description": "Review code for bugs, security, and performance",
      "version": "1.0.0"
    }
  ]
}
```

Install:

```text
/plugin marketplace add ./company-marketplace
/plugin install quality-review-plugin@company-tools
```

Plugins are copied into an installation cache. Do not depend on paths outside the package such as ../shared-utils; those files are not automatically included.

## Versions and dependencies

| Mechanism | Purpose |
| --- | --- |
| Plugin version | Update identity |
| Git commit source | Commits can act as versions when no version is specified |
| Dependency constraints | Compatible dependency ranges |
| Managed marketplace | Restrict allowed sources |
| Lock/pinned commit | Reproducibility |

Constrain plugin dependencies so upstream breaking changes do not unexpectedly alter team workflows.

## Recommendations

| Signal | Use |
| --- | --- |
| Paths | go.mod, package.json, terraform directories |
| Language | Relevant intelligence/checking tools |
| Internal framework | Company plugins in matching repositories |
| CLI marker | Suggest a related plugin |

Recommendations do not force installation. Use enabledPlugins/managed settings for enforced deployment.

## Security guidance

| Layer | Cost | Trigger |
| --- | --- | --- |
| Per-edit patterns | No model call | After edits |
| End-of-turn review | Model call | Review diff after a turn |
| Commit/push review | Model call | Agent invokes commit/push through Bash |

```text
/plugin install security-guidance@claude-plugins-official
/reload-plugins
```

Project enablement:

```json
{
  "enabledPlugins": {
    "security-guidance@claude-plugins-official": true
  }
}
```

Custom rules:

```markdown
# .claude/claude-security-guidance.md

- Do not log customer_id or account_number at INFO level.
- Check the admin role before every /admin route.
- Use timing-safe token comparison.
```

Pattern rules:

```yaml
patterns:
  - rule_name: internal_api_key
    substrings: ["sk_live_", "AKIA"]
    reminder: "Possible hard-coded credential; use the secret manager."
```

This supplements human review, SAST, and blocking hooks; it does not replace them.

## Enterprise governance

| Goal | Approach |
| --- | --- |
| Internal catalogs only | Managed marketplace restrictions |
| Universal security plugin | Distribute enabledPlugins |
| Restrict user MCP | managed-mcp.json or strictPluginOnlyCustomization |
| Track provenance | Inspect plugin list/configuration |
| Control context cost | Review tool/context cost before installing |
| Diagnose failures | Plugin Errors tab |

Treat hooks and executables as software supply-chain code: review, pin, record changes, and restrict publication.

## Cache effects

| Change | Effect |
| --- | --- |
| Skill-only plugin | Adds descriptions/commands; prefix may change |
| LSP | Adds diagnostics, usually not large per-turn schemas |
| MCP plugin | Upfront schemas can significantly alter prefix |
| Reload | Next turn applies changed definitions |
| Version update | Changed manifests/skills/tools can reduce reuse |
| Tool search | Reduces large MCP-definition impact where supported |

Monitor persistent cache-creation growth when many plugins are enabled.

## Official references

- [Discover plugins](https://code.claude.com/en/docs/en/discover-plugins.md)
- [Marketplaces](https://code.claude.com/en/docs/en/plugin-marketplaces.md)
- [Dependencies](https://code.claude.com/en/docs/en/plugin-dependencies.md)
- [Hints](https://code.claude.com/en/docs/en/plugin-hints.md)
- [Relevance](https://code.claude.com/en/docs/en/plugin-relevance.md)
- [Reference](https://code.claude.com/en/docs/en/plugins-reference.md)
- [Security guidance](https://code.claude.com/en/docs/en/security-guidance.md)
